ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Urgent - Expression Engine Security Breach

December 07, 2010 2:54pm

Subscribe [3]
  • #1 / Dec 07, 2010 2:54pm

    mekon

    7 posts

    We’re not sure how it happened but our site is now getting new members registered about once an hour.  We noticed when we had 2000 new members, and their member pages were redirecting to a gambling website.

    We have set our MemberShip preferences to:
    Allow New Member Registrations?    -  No  
    Require Member Account Activation?  - Manual Activation by Admin  
    Require Terms of Service         -  Yes
    Allow ... localization preferences? -  No  
    Enable Membership Captcha       -  Yes
    Default Member Group Assigned to New Members - Pending

    And we still have new accounts being created.  There must be a script still running somewhere.  Please help!!

    [Mod Edit: Moved to the EE 1 Technical Support forum]

  • #2 / Dec 07, 2010 3:00pm

    mekon

    7 posts

    PS - Why does it say ‘Summer student’ under my name on the user details on the left?

  • #3 / Dec 07, 2010 3:34pm

    Ingmar

    29245 posts

    What version and build of EE are you using? Any extensions? Do you’ve got a link? (The “Summer Student” is keeping with our “lab” (EllisLab, get it?) theme. Personally I think it’s funnier then “newbie” or other such terms of endearment.)

  • #4 / Dec 08, 2010 3:39am

    mekon

    7 posts

    Here’s all the modules/extensions/plug-ins I could find: 

    ExpressionEngine v 1.6.5

    Modules:
    Comment     1.0
    Email     1.1
    Emoticon   1.0
    Freeform   2.5.7
    Mailing List   2.0  
    Member     1.34
    Query     1.0
    Referrer   1.1
    RSS     1.0
    Search     1.0
    Statistics   1.0
    Trackback   1.0
    Weblog     1.0

    Plugins:
    Character Limiter   1.0
    Magpie RSS Parser   1.4
    Randomizer     1.0
    Search Marker     1.0
    TruncHTML     1.2
    Word limiter     1.0
    XML Encode     1.2

    Extensions:
    Set Inverse Relationships 1.0


    Many thanks

  • #5 / Dec 08, 2010 4:54am

    mekon

    7 posts

    When you say ‘link’ you mean link to our website?  It’s www dot mekon dot com

  • #6 / Dec 08, 2010 5:12am

    mekon

    7 posts

    Oh yes - and we’re also running MSM with 4 websites going.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases